Sonar is a security researcher's Swiss army knife for finding and exploiting vulnerabilities that require out-of-band interactions
☆21Jul 12, 2026Updated last week
Alternatives and similar repositories for sonar
Users that are interested in sonar are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Framework for blind boolean-based sql injections exploatation. Use it if sqlmap does shit.☆29Mar 26, 2022Updated 4 years ago
- PoC of using Directus as ASPM☆13May 31, 2024Updated 2 years ago
- A list of checks with tips for analyzing the security of Android applications☆14Nov 19, 2019Updated 6 years ago
- RSEScan is a command-line utility for interacting with the RSECloud. It allows you to fetch subdomains and IPs from certificates for a gi…☆17Jun 7, 2024Updated 2 years ago
- Jeopardy CTF platform☆12Jan 3, 2023Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Various wordlists for bruteforce☆35Nov 9, 2021Updated 4 years ago
- ☆33Oct 7, 2023Updated 2 years ago
- Check bitrix vulnerabilities☆100Jan 22, 2024Updated 2 years ago
- A python library to interact with Pwndoc instances for pentest reports generation☆23May 19, 2025Updated last year
- Yet Another Wordlists Repo☆138Jan 6, 2022Updated 4 years ago
- The Burp extension to check JWT (JSON Web Tokens) for using keys from known from public sources☆142Sep 21, 2020Updated 5 years ago
- Oyedata is a tool to perform OData assessments☆13Aug 3, 2012Updated 13 years ago
- SAP penetration testing Web and network cheatsheet☆17May 15, 2022Updated 4 years ago
- ☆37Jul 1, 2026Updated 3 weeks ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- This automation protect against subdomain takeover on AWS env which also send alerts on slack.☆11Aug 1, 2021Updated 4 years ago
- A simple sveltekit template to start a project using tailwind & daisyui☆11Jan 5, 2024Updated 2 years ago
- Extract uncompiled, uncompressed SPA code from Webpack source maps. A fork of @rarecoil's work.☆13Jul 11, 2024Updated 2 years ago
- API for Asset Service☆15Aug 15, 2024Updated last year
- Python utility to takeover domains vulnerable to AWS NS Takeover☆86Feb 2, 2023Updated 3 years ago
- Uzbek cyrillic/latin alphabetic, upper/lower/capital-case, name/surname/patronymic wordlists (dictionaries) and their combinations☆13Aug 4, 2022Updated 3 years ago
- Bash Enumeration Script☆18Oct 18, 2019Updated 6 years ago
- gruvbox dark theme for tmux☆14Aug 25, 2021Updated 4 years ago
- A vulnerable application exposing Spring Boot Actuators☆123Feb 25, 2019Updated 7 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Деобфускатор Bitrix☆19Feb 26, 2026Updated 4 months ago
- ☆19Jan 1, 2021Updated 5 years ago
- Chase subdomains by parsing the results of Google and Yandex search results☆16Sep 29, 2023Updated 2 years ago
- FVWA (Flask Vulnerable Web Application)☆18Oct 14, 2024Updated last year
- ☆14Aug 10, 2022Updated 3 years ago
- PoC for distributed NTP reflection DoS (CVE-2013-5211)☆10Oct 4, 2019Updated 6 years ago
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆28May 23, 2026Updated 2 months ago
- Finding secrets in various (non-text) popular files.☆55Oct 21, 2025Updated 9 months ago
- ToolShell scanner - CVE-2025-53770 and detection information☆18Dec 7, 2025Updated 7 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- AES-GEM (AES Galois Extended Mode) implementation.☆14May 19, 2026Updated 2 months ago
- GitLab CI security tools runner☆18Feb 3, 2023Updated 3 years ago
- Generates a DEBUG PIN for flask applications based on Werkzeug☆20Nov 22, 2023Updated 2 years ago
- a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to …☆31Oct 21, 2025Updated 9 months ago
- ☆13Feb 4, 2025Updated last year
- A tool for deploying a forward proxy in your Yandex Cloud infrastructure to change your IP address (almost) each request.☆23Jan 8, 2026Updated 6 months ago
- CVE-2025-26794: Blind SQL injection in Exim 4.98 (SQLite DBM)- exploit writeup☆15Mar 19, 2025Updated last year